Bug#1082902: bookworm-pu: package nghttp2/1.52.0-1+deb12u2
On Sat, Sep 28, 2024 at 02:38:29AM +0300, Adrian Bunk wrote:
> Package: release.debian.org
> Severity: normal
> Tags: bookworm
> User: release.debian.org@packages.debian.org
> Usertags: pu
> X-Debbugs-Cc: security@debian.org, Tomasz Buchert <tomasz@debian.org>
>
> * CVE-2024-28182: unbounded number of HTTP/2 CONTINUATION frames DoS
> (Closes: #1068415)
> * nghttp2_option_set_stream_reset_rate_limit was added in
> 1.52.0-1+deb12u1, add to debian/libnghttp2-14.symbols
>
> Tagged moreinfo, as question to the security team whether they want
> this in -pu or as DSA.
pu is fine, thanks!
Cheers,
Moritz
Reply to: